Privacy notice
Last updated 28 August 2026
Draft — not yet reviewed by a lawyer
This text describes accurately what the software does with data, and is intended as the starting point for review by a qualified adviser in the relevant jurisdiction. It is not legal advice and is not in force. Passages in square brackets are decisions that have not been made yet.
1. Who this is about
The Internship ROI Simulator ("the Service") is operated by Opportunities Nearby FZE, Sharjah Research Technology and Innovation Park (SRTIP), Sharjah, United Arab Emirates — Licence No. 11131 ("we").
Two different relationships matter here, and they carry different duties:
- For the people who sign up — the administrators who create an account — we decide what is collected and why. We are the controller of that data.
- For the interns and supervisors an organisation adds to a programme, the employer decides what to record and why; we hold and process it on their instructions. The employer is the controller and we act as processor. If you are an intern or supervisor asking why your performance is recorded, your employer is the right first contact — though you can always reach us at the address in section 10.
This split follows the controller and processor definitions in the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021 — the "PDPL"), which applies to us as an SRTIP establishment, and it holds: we are controller for account holders, and processor for the people an employer adds. Because the PDPL requires a processor to act on the controller's documented instructions, we put a written data-processing agreement in place with each customer — if your organisation does not have one yet, ask at the address in section 10 and we will provide it. Where another regime also applies to a customer — the GDPR, or the DIFC or ADGM data-protection laws — that agreement is where its requirements are addressed.
2. What the Service stores
Everything the Service holds falls into five groups.
- Account data. Your email address, a password (stored only as a hash, never in readable form), your display name and an optional profile picture.
- Programme roster. For each intern and supervisor an administrator adds: full name, email address and department. For interns, an administrator may also record whether the person is a UAE national — optional, used only to report the Emiratisation quota saving the employer is claiming, and never inferred by us from a name or an email address. Invitation emails are stored until the invitation is used or withdrawn.
- Work and evidence. The notes interns write when submitting work, any files they attach, and any links they provide.
- Assessment. Supervisors' written feedback, per-criterion ratings, and the KPI measurements calculated from accepted work. This is the most sensitive category the Service holds: it is a named person's performance record.
- Organisation and planning data. Company name and optional logo, programme details, and the cost and value assumptions entered into the ROI wizard. These are business figures, not personal data, but they are stored alongside it.
Analytics. With your consent, the Service uses Google Analytics (GA4) to understand how its pages are used. Nothing loads until you actively accept a banner shown on first visit; declining, or leaving it unanswered, leaves the Service exactly as before — no third-party script runs, and no cookie is set beyond the one that keeps you signed in. The Service sets no advertising or profiling cookie of any kind, and analytics data is never sold.
3. Where it is stored, and who else touches it
The database and uploaded files are hosted on Supabase in the eu-central-2 region (Zurich, Switzerland). The application itself is served by Cloudflare from its global edge network. This means personal data about people in the United Arab Emirates is stored outside the UAE.
Switzerland was chosen for this reason. It holds an adequacy decision from the European Commission and appears on the lists of adequate jurisdictions published by the ADGM and the DIFC, and its own Federal Act on Data Protection applies to the data while it is there.
The UAE Data Office has not yet published the PDPL's executive regulations or an adequacy list of its own. Until it does, we rely on Article 23 of the PDPL, which permits a transfer out of the UAE under a contract holding the recipient to the PDPL's standard of protection: Supabase's data-processing addendum, which incorporates the EU standard contractual clauses, is that contract, and Swiss data-protection law applies to the data while it is in Zurich. If the Data Office publishes rules that ask for more, we will comply and update this notice.
Our processors are:
- Supabase — database, authentication and file storage (Zurich, Switzerland).
- Cloudflare — application hosting and content delivery.
- Resend — delivery of sign-in, invitation and notification emails.
- Google Analytics — usage analytics, only for visitors who accept the consent banner described in section 2 (United States).
Consent is the basis for this transfer, and it suffices: Article 23 of the PDPL permits a transfer made with the data subject's express consent, and nothing is sent to Google unless a visitor actively accepts the banner. For visitors protected by the GDPR, Google LLC is additionally certified under the EU–U.S. Data Privacy Framework, which the European Commission has found adequate. Declining the banner keeps this paragraph from applying to you at all.
We do not sell personal data, and we do not share it for anyone else's marketing.
4. Who can see what
Access is enforced in the database itself, not only in the interface, so a person cannot reach data by guessing a web address:
- Interns see their own tasks, their own submissions and their own KPI scores. They cannot see other interns, and they cannot see any cost or return figure.
- Supervisors see the interns assigned to them and the work those interns submit. They cannot see the programme's economics.
- Administrators see their own organisation's programmes, people and figures — and nothing belonging to any other organisation.
Uploaded files are held in private storage with no public address. When a file is opened, the Service issues a link that expires after five minutes.
5. Report share links
An administrator can create a link that shows a generated report to someone without an account. Anyone holding that link can read the report until it expires or is withdrawn, so it should be treated as confidential.
A shared report contains programme-level figures — cost, return, delivery counts and KPI results. It does not name individual interns and does not include their submissions, feedback or individual ratings. The Service records when a link is opened and how many times, and keeps that record after the link is withdrawn.
6. How long it is kept — and what cannot be deleted
Some records in the Service are deliberately permanent. Submissions, reviews, ratings, KPI measurements, saved ROI snapshots and the audit log are append-only: the software refuses to delete or rewrite them, so that a performance record cannot be quietly altered after the fact and a report can always be reproduced from what was true when it was generated.
That protection has a cost, and we would rather state it than hide it: a request to erase an individual's assessment history cannot be satisfied by deleting those rows. Where erasure is required by law, it would have to be met by removing the identifying fields that link a record to a person, or by deleting the organisation's account in full.
Retention periods are:
- Account data — for as long as your account exists, deleted within 30 days after it is closed.
- Roster, work, evidence and assessment records — for as long as the organisation's account exists. Within 90 days of an organisation's account closing, we delete this data or remove the fields that identify a person in it, keeping only what the next line requires.
- Invoices and payment records — seven years after the end of the relevant tax period, which UAE tax law requires.
- The audit log — five years, after which entries are anonymised.
Erasure requests go to the address in section 10 and are executed by us within 30 days: for the append-only records above, by removing the fields that link a record to a person; for everything else, by deletion. Where the employer is the controller, we act on the employer's instruction.
7. Your rights
Subject to the law that applies to you, you may ask for a copy of your data, ask for inaccurate data to be corrected, object to or restrict how it is used, or ask for it to be deleted — bearing section 6 in mind. If an employer entered your data, please ask them first; we will help them respond.
You can correct your own name and profile picture at any time on the My account screen.
8. Young people
Interns are often students and may be under 18. The Service has no age gate and never asks a person's date of birth, because an employer — not the software — decides who joins a programme. Where an intern is a minor, the employer is responsible for having a lawful basis to record their performance, including any consent a guardian must give.
For UAE programmes the position is this: the Labour Law (Federal Decree-Law No. 33 of 2021) already requires an employer taking on anyone aged 15 to 17 to hold a juvenile work permit and the written consent of the person's guardian, and that consent must cover the recording of the intern's work and performance that the programme involves. We hold no more data about a minor than about any other intern, and every protection in this notice applies equally. An employer running a programme under another jurisdiction's rules on children's data is responsible for meeting them before adding the intern.
9. Security
Access rules are enforced by the database on every read and write. Files are private by default and reachable only through short-lived links. Passwords are stored as hashes. Administrative actions are written to an append-only audit log.
No system is perfectly secure. If a breach affects your data we will act on the notification duties that apply to us. If a breach is likely to prejudice your privacy or the security of your data, we will notify the UAE Data Office and — where the risk to you is serious — you directly, without undue delay and in any event within 72 hours of becoming aware of it. The PDPL sets no numeric deadline until its executive regulations are published; 72 hours is the strictest standard among the regimes that touch this Service, so it is the one we adopt. Where we hold data as an employer's processor, we notify the employer without undue delay so it can meet its own duties.
10. Contact and changes
Questions about this notice or a request about your data: support@internroi.com, Block B, B55-200, Sharjah Research Technology and Innovation Park (SRTIP), Sharjah, United Arab Emirates. A Data Protection Officer is not currently required and none is appointed: the PDPL requires one only for high-risk processing — large-scale or systematic evaluation of sensitive personal data, or novel technologies — and performance records are not sensitive data as the PDPL defines it, nor is our scale large. Privacy questions sent to the address above reach the people who operate the Service directly. We will revisit this when the executive regulations are published or if what we process changes.
If we change this notice we will update the date at the top and, where the change is significant, tell account holders directly.